SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-0565

Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.

LOW 2.1EPSS 0.44%

Does this matter?

Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.

Description

Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.

CVSS 2.0
2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS
0.44% probability · 38th percentile
CISA KEV
Not listed
Affected
mandrakesoft/mandrake multi network firewall · gentoo/linux · linux/linux kernel · mandrakesoft/mandrake linux · mandrakesoft/mandrake linux corporate server · trustix/secure linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.